High severityNVD Advisory· Published Jul 7, 2026· Updated Jul 8, 2026
CVE-2026-53729
CVE-2026-53729
Description
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, any authenticated user can download (/exportCenter/download/{id}), delete (/exportCenter/delete), retry (/exportCenter/retry/{id}), or generate download links (/exportCenter/generateDownloadUri/{id}) for export tasks belonging to other users by manipulating the task ID parameter, and the /exportCenter/download/{id} endpoint is whitelisted from authentication, allowing unauthenticated access to exported files. This issue is fixed in version 2.10.24.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.